package com.ita.dao.impl;

import java.sql.Connection;
import java.sql.PreparedStatement;
import java.sql.ResultSet;
import java.sql.SQLException;

import com.ita.dao.UserDao;
import com.ita.pojo.User;
import com.ita.util.DBUtil;

public class UserDaoImpl implements UserDao {

	@Override
	public User findUser(String username, String password) {

		String sql = "select * from users where username=? and password=?";
		Connection con = null;
		PreparedStatement pst = null;
		ResultSet rs = null;
		User c = null;
		try {
			con = DBUtil.createByJNDI();
			pst = con.prepareStatement(sql);
			pst.setString(1, username);
			pst.setString(2, password);
			rs = pst.executeQuery();
			if (rs.next()) {
				c = new User();
				c.setId(rs.getInt("id"));
				c.setUsername(rs.getString("username"));
				c.setPassword(rs.getString("password"));
			}
		} catch (SQLException e) {
			e.printStackTrace();
		} finally {
			DBUtil.close(con, pst, rs);
		}
		return c;
	}

}
